OS command injection vulnerability in WRC-X3000GSN v1.0.2, WRC-X3000GS v1.0.24 and earlier, and WRC-X3000GSA v1.0.24 and earlier allows a network-adjacent attacker with an administrative privilege to execute an arbitrary OS command by sending a specially crafted request to the product.
References
Link | Resource |
---|---|
https://jvn.jp/en/vu/JVNVU97499577/ | Third Party Advisory |
https://www.elecom.co.jp/news/security/20231212-01/ | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: jpcert
Published: 2023-12-12T08:58:47.925Z
Updated: 2023-12-12T08:58:47.925Z
Reserved: 2023-11-30T01:25:31.380Z
Link: CVE-2023-49695
JSON object: View
NVD Information
Status : Analyzed
Published: 2023-12-12T09:15:08.950
Modified: 2023-12-15T14:17:40.347
Link: CVE-2023-49695
JSON object: View
Redhat Information
No data.
CWE